Last updated: 19 September 2026.
Data Processing Agreement (DPA)
Agreement on processing personal data under Article 28 GDPR between the organisation using the service (Controller) and the provider of Steinkauz Cloud identified in the Legal Notice (Processor).
This DPA becomes part of the cloud contract when the Controller uses Steinkauz Cloud and has personal data processed in doing so. It does not apply to a Private Deployment on the customer's infrastructure insofar as we do not ourselves process personal data on the customer's behalf there.
1. Subject matter and duration
- The subject matter is processing personal data on behalf of the Controller in providing Steinkauz Cloud (accounts in an organisational context, chat, file attachments, Platform API, controls and records).
- The duration corresponds to the term of the cloud contract plus the deletion and retention periods stated in the Privacy Policy, insofar as statutory obligations require longer retention.
- The Controller gives instructions through the product features, documentation and — where necessary — in text form to contact@steinkauz.ai.
2. Nature, purpose, data and data subjects
| Nature and purpose | Storing, transmitting, displaying, deleting and otherwise processing content entered into the platform by the Controller or its users, and operating the infrastructure required for this |
| Categories of personal data | Content determined by the Controller (such as messages, files and usage metadata); account associations insofar as needed for tenant separation |
| Data subjects | Persons determined by the Controller (such as employees, customers and other communication partners) |
| Inference | Model calls are made on the Controller's instructions to providers chosen by the Controller (BYOK / own gateway). These providers are processors of the Controller. The Processor transmits the instructed data to the selected provider. |
The Controller is responsible for the lawfulness of processing and for the content. The Processor informs the Controller without undue delay if, in its opinion, an instruction infringes data protection law.
3. Obligations of the Processor
The Processor:
- Processes personal data only on documented instructions from the Controller, including for transfers to a third country, unless Union or Member State law requires otherwise; in that case, it informs the Controller of that legal requirement before processing, unless that law prohibits this on important grounds of public interest;
- Ensures that persons authorised to process the data have committed themselves to confidentiality or are subject to an appropriate statutory obligation of confidentiality;
- Implements the technical and organisational measures described in the annex;
- Engages sub-processors only in accordance with section 4;
- Assists the Controller, where possible through appropriate technical and organisational measures, in fulfilling data subject rights;
- Assists the Controller, taking into account the nature of processing and the information available, in fulfilling its obligations under Articles 32 to 36 GDPR, in particular concerning security measures, personal data breaches, data protection impact assessments and consultations with the supervisory authority;
- At the end of the processing services, deletes or returns all personal data at the Controller's choice and deletes existing copies, unless there is a statutory obligation to retain them;
- Makes available to the Controller the information needed to demonstrate compliance with these obligations and allows audits (section 6).
4. Sub-processors
- The Controller authorises the engagement of the entities listed under Sub-processors.
- The Processor informs the registered organisation contact by email of intended additions or replacements with reasonable advance notice, allowing the Controller to object before engagement. If no agreement can be reached, the Controller may terminate the cloud contract for cause.
- The Processor contractually imposes obligations on sub-processors corresponding to those in this DPA insofar as relevant to their part of the service. It remains responsible to the Controller for the sub-processors' compliance with those obligations.
- Model providers and gateways independently selected by the Controller are not sub-processors of the Processor.
5. Processing locations
The database, object storage, Redis and Vercel Functions operate in the European regions specified in the Service Provider List. Some service providers also process data outside the EU or EEA; an EU region alone does not exclude this. Transfers to third countries require compliance with Articles 44 et seq. GDPR, in particular an applicable adequacy decision or appropriate safeguards.
These infrastructure locations may be changed within the EU or EEA while maintaining the same level of protection; the service provider list will be updated accordingly. The Processor informs the Controller in advance by email of material changes to processing locations. The provisions on sub-processors and transfers to third countries remain unaffected.
6. Evidence and audits
- The Processor provides the information needed to demonstrate compliance with this DPA, in particular a description of the technical and organisational measures and information about their implementation. Available provider reports may be supplied additionally where disclosure is permitted. No certifications of our own or specific attestations are promised.
- The Processor allows and contributes to audits, including inspections, conducted by the Controller or an auditor appointed by the Controller. The parties agree on the procedure and scope taking account of the audit purpose, confidentiality and ongoing operations. Statutory audit and information rights are not restricted by this.
7. Notification of breaches
The Processor notifies the Controller without undue delay after becoming aware of a personal data breach. The notification includes the information required by law insofar as available. Contact: contact@steinkauz.ai.
8. Liability
Liability under this DPA is governed by the Terms of Service unless the GDPR mandatorily provides otherwise. Article 82 GDPR remains unaffected.
9. Final provisions
- The law of the Federal Republic of Germany applies.
- In the event of a conflict, the provisions of this DPA take precedence over the Terms of Service insofar as the matter concerns data protection obligations for processing on behalf of the Controller.
- The German version is authoritative unless mandatory law requires otherwise. Mandatory statutory rights and rules of interpretation remain unaffected.
Annex — Technical and organisational measures (TOMs)
The following measures describe the current cloud platform. Details may change as the service develops without reducing the level of protection.
- Physical and logical access control: Hosting with professional data centre and cloud providers; restricted and authenticated administrative access; no publicly accessible management interfaces for customer content.
- Separation: Logical tenant separation by organisation and user-specific access checks; further access only on the basis of permissions, a share created by the user or necessary administrative operations.
- Transmission: Transport encryption (TLS) for public endpoints.
- Storage: AES-256-GCM encryption at the application layer for stored message text, conversation titles, supplied model provider keys and content snapshots of model and tool calls. Uploaded files and all metadata are not generally covered by this. The service can decrypt encrypted content for the instructed processing; this is not end-to-end encryption.
- Input and disclosure: Logging of security- and billing-related events; transmission to inference providers only on instructions (selected model / endpoint).
- Availability and deletion: Operation on managed cloud infrastructure; use of the recovery functions included in the relevant infrastructure contract. Separate archiving of all customer content is not promised. Daily cleanup of expired content: conversations by default 30 days after the last message, files 30 days after upload, and content snapshots of model and tool calls 30 days after creation or request, respectively. Statutory obligations concerning security and recoverability under Article 32 GDPR remain unaffected.
- Processing control: Processing only within the product features and documented instructions; sub-processors bound by contract.
- Separation of measurement and content: Browser-related product analytics only with consent; technical API and operational events may be processed independently. Prompt and response bodies are not recorded in LLM telemetry.
This annex forms part of the DPA. The effectiveness of the technical and organisational measures is reviewed regularly in light of the processing risks and adjusted as needed.